Privacy policy
Last updated: 11 September 2026
1. The short version
We collect what running the Service needs: your account details, subscription state, content you deliberately create and the operational information needed to keep the Service secure and available. We also use the Google tag with consent mode for optional Google Analytics. Analytics storage starts denied, and you can change your choice later through Cookie settings. We do not use Google advertising storage and we do not sell personal data. Your card details go to Stripe and never touch our servers.
2. Who is responsible
Scoutopedia (scoutopedia.com) is the data controller for the personal data described here. Contact for anything in this policy: support@scoutopedia.com.
3. What we collect and why
- Account data — your email address, an optional display name, and a password (stored only as a hash by our authentication provider). Used to sign you in, secure the account and, rarely, to contact you about it. Legal basis: performing our contract with you.
- Billing data — if you subscribe or book advertising: your subscription’s status, its Stripe identifiers, and what it entitles you to. Stripe holds the card, the invoices and the payment history. Legal basis: contract, and legal obligations around payment records.
- Content you create — shortlists, ratings and scouting notes (stored scoped to your account and readable by nobody else through the Service), and advertising creatives if you book a campaign. Legal basis: contract.
- Operational logs — our hosting provider keeps short-lived request logs such as IP address, user agent and timing, used to run and secure the Service. Legal basis: legitimate interest in keeping the Service available and preventing abuse.
- Optional product analytics — Scoutopedia installs the Google tag in consent mode with analytics storage denied by default. While storage is denied, Google Analytics cannot read or write Scoutopedia’s first-party analytics cookies; the tag may send limited cookieless consent and measurement signals. If you choose Allow analytics, Google Analytics records page views, standard usage information such as referrer, browser/device category and approximate geography, and high-level product events when they happen, such as successful account activation, shortlist creation, starting a Premium checkout and completing a Premium checkout. For Premium checkout events we send the plan code, currency and amount; after a completed checkout we also send the Stripe Checkout transaction id so subscription revenue can be measured without counting the same purchase twice. Card details are never sent to Google Analytics. Scoutopedia sends page paths without query strings, so search terms, filters and URL parameters are deliberately omitted from page-view events. We do not attach your Scoutopedia account ID, email address, shortlist names or scouting notes to analytics events. Optional analytics storage and detailed usage analytics rely on your consent.
We do not build advertising profiles about you and we do not use the Scoutopedia analytics implementation to track you across unrelated websites. The advertising airtime beacon on the tactics board counts on-screen seconds in aggregate without recording who was watching.
4. Cookies and browser storage
The Service uses essential browser storage needed for the product to work: session cookies that keep you signed in, a timezone cookie used to show fixtures on your local clock and, for administrators only, a preview cookie that can show the site as a different tier. The interface also remembers preferences such as theme locally in your browser.
Your analytics choice is stored locally in your browser so we can remember it. The Google tag is loaded with analytics_storage denied unless you have already chosen Allow analytics. With analytics storage denied it does not read or write first-party Google Analytics cookies, although Google may receive cookieless consent and measurement signals. If you choose Allow analytics, Google Analytics may set first-party analytics cookies such as _ga. You can withdraw that consent at any time through Cookie settings; Scoutopedia then returns analytics storage to denied, stops sending its consented product events and removes accessible Google Analytics cookies from the site.
5. Who processes data for us
- Supabase — authentication and database hosting. Our project is hosted in the EU (Ireland).
- Stripe — payment processing for subscriptions and advertising. Stripe is the controller of the payment data it collects at checkout; see Stripe’s own privacy policy.
- Vercel — application hosting and delivery, including the operational logs above.
- Google Analytics — the consent-aware Google tag and optional product analytics. With analytics storage denied Google may receive limited cookieless signals; after you allow analytics it receives the limited usage information described in section 3 to provide aggregated analytics reports to Scoutopedia.
Where a processor operates outside the UK/EEA, transfers rely on the safeguards applicable to that provider and service.
The football statistics themselves come from licensed sports-data providers and concern professional players in their public, professional capacity — squad lists, appearances and match statistics published as part of the sporting record.
6. How long we keep things
Account data and your content are kept while the account exists and deleted when it is. Deleting the account deletes shortlists and notes with it. Billing records survive as long as tax and accounting law requires them to. Operational logs expire according to the hosting provider’s retention settings. Google Analytics data is retained according to the retention settings of the Scoutopedia Analytics property.
7. Your choices and rights
You can allow or refuse analytics when the choice is first shown, and reopen Cookie settings later from the public site footer or, when signed in, from the account menu. Refusing analytics does not restrict any Scoutopedia feature.
Under UK and EU data protection law you can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict processing, and take your data with you. Most account information can be seen or changed directly on your account page; for the rest, email support@scoutopedia.com and we will respond within the applicable legal timeframe. You can also complain to your supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk).
8. Children
The Service is not directed at children and accounts require you to be at least 16. If you believe a child has created an account, contact us and we will remove it.
9. Changes
If this policy changes materially we will say so on the Service before the change takes effect. The date at the top is the date of the current version.